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Information Commissioner’s Office 


Sent by email only to: 


XXXX 
Email: xxxx 


25 October 2021 


RE: The Information Commissioner's Office (ICO) audit of xxxx and 
subsequent follow up work. 


Dear XXxx, 


As you may be aware, during 2019 the ICO `s Audit Team conducted a compulsory 
audit of xxxx. The purpose of the audit was to provide the ICO with an assurance 
of the extent to which your party, within the scope of the audit, was complying 
with data protection legislation. Your party engaged positively with the audit 
process and seemed to welcome the opportunity to discuss and exchange data 
protection issues and examples of good practice with the ICO’s Audit Team. 


The audit however found some considerable areas for improvement in both 
transparency and lawfulness and we recommended several specific actions to bring 
your party’s processing in compliance with data protection laws. In addition, we 
recommended that your party implemented several appropriate technical and 
organisational measures to meet the requirements of the accountability principle 
of the legislation. Overall, at the time that the audit was conducted, there was a 
limited level of assurance that processes and procedures were in place and were 
delivering data protection compliance. The ICO published their ‘Summary of audits 


of data protection compliance by UK political parties’ report in November 2020. 


More recently we conducted follow up work with your party to determine the extent 
to which our recommendations from the original audit had been actioned. I attach 
a copy of our Follow Up Report as a separate document to this letter for your 
information. 


The follow up work concluded that your party has made meaningful progress to or 
completed all the actions agreed in the original audit and where some outstanding 
actions exist, acceptable progress is being made to mitigate the risk of non- 
compliance. 


1CO. 


Information Commissioner’s Office 


The ICO recognises that society benefits from political parties that want to keep in 
touch with people, through more informed voting decisions, better engagement 
with hard to reach groups and the potential for increased engagement in 
democratic processes. The use of new technologies and strategies that utilise 
personal information for political campaign purposes is only going to continue to 
grow. Trust is crucial in this process, not only in informing our confidence in political 
parties, but also in democracy more broadly. The transparency and accountability 
required by data protection is a key aspect in developing this trust in our 
democracy. 


Therefore, I hope that the measures and processes put in place as a result of the 
audit continue to be effective, adhered to and embedded in the future, particularly 
in future campaigning by your party. The ICO retains the right to take further 
action if issues around your party’s compliance come to our attention in the future. 


Finally I would like to thank those in your party that were directly involved in the 
engagement for their co-operation and work. 


Yours sincerely, 


Head of Assurance, ICO. 


